• Register
    • Help

    striker  0 Items
    Currently Supporting
    • Home
    • News
      • VaultWiki News
      • Visit the Wiki
    • Forum
    • Wiki
    • Support
    • What's New?
    • Buy Now
    • Manual
    • 
    • Home
    • VaultWiki Security Update: October 2019

    1. Welcome to VaultWiki.org, home of the wiki add-on for vBulletin and XenForo!

      VaultWiki allows your existing forum users to collaborate on creating and managing a site's content pages. VaultWiki is a fully-featured and fully-supported wiki solution for vBulletin and XenForo.

      The VaultWiki Team encourages you to join our community of forum administrators and check out VaultWiki for yourself.

    • VaultWiki Security Update: October 2019

      by
      pegasus
      • View Profile
      • View Forum Posts
      • View Blog Entries
      • Visit Homepage
      • View Articles
      Published on October 12, 2019 12:50 PM
      0 Comments Comments
      As of October 12, the security patches for October 2019 are now available.

      Issue List

      VWE-2019-5363 is a Permissions Escalation issue, where users are able to make unmoderated edits to the index and area pages, as long as they can make unmoderated edits to regular pages. The issue affects all versions of the 4.x series.

      VWE-2019-5360 is a Permissions Escalation issue, where users can accidentally rename pages with HTML entities in the title, even if they don't have permission to rename pages. The issue affects all versions of the 4.x series.

      VWE-2019-5375 is a Permissions Escalation issue, where regardless of other applicable types, users can rename any attachment as long as they have permission to rename attachments, and can rename other types of pages as long as they have permission to rename regular pages. The issue affects all versions of the 4.x series.

      Patches

      The following patches address the aforementioned issues:
      • 4.0.27 Patch Level 1
      • 4.0.26 Patch Level 3
      • 4.0.25 Patch Level 5


      4.1.x Issues

      Since beta versions are not subject to the same patching policy as stable versions, the following issues will be patched in the next release of the 4.1.x branch, 4.1.0 Beta 4, in addition to any relevant issues listed above.

      VWE-2019-5361 is a Permissions Escalation issue, where users can create new collaborative feeds in no area without awaiting approval, as long as they have global permissions to create collaborative feeds. The issue affects 4.1.0 Alpha 1 and higher.

      VWE-2019-5391 is a Phishing issue, where user-positioned elements are not restricted within the relevant position's container. The issue affects 4.1.0 Alpha 1 and higher.

      Notes

      We recommend that all users running VaultWiki in a production environment update to a patched release as soon as they are able.
    • Contact Us
    • License Agreement
    • Privacy
    • Terms
    • Top
    All times are GMT -4. The time now is 9:13 PM.
    This site uses cookies to help personalize content, to tailor your experience, and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Learn more… Accept Remind me later
  • striker
    Powered by vBulletin® Version 4.2.5 Beta 2
    Copyright © 2025 vBulletin Solutions Inc. All rights reserved.
    Search Engine Optimisation provided by DragonByte SEO (Pro) - vBulletin Mods & Addons Copyright © 2025 DragonByte Technologies Ltd.
    Copyright © 2008 - 2024 VaultWiki Team, Cracked Egg Studios, LLC.